Threat Bulletin 1155: SYN flood against a healthcare portal platform in Western Europe

On Thursday 31 July 2025 at 01:02 UTC, a SYN flood targeted a healthcare portal customer in Western Europe. The attack peaked at 63.1 Gbps and lasted 181 minutes. Traffic originated from 3097 autonomous systems in 69 countries, predominantly hijacked home routers.

Vector SYN flood
Peak 63.1 Gbps
Duration 181 min
Time to mitigation 0.452 s
Attack traffic reaching origin 0.087%
Legitimate traffic challenged 0.80%

Timeline

The attack was preceded by an extortion email received two days earlier. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 20 points of presence.

What the customer saw

No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.

Recommendations

  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Enable authenticated origin pulls.
  • Review allow-listed partner ranges quarterly.

6 thoughts on “Threat Bulletin 1155: SYN flood against a healthcare portal platform in Western Europe”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top